threat-intel Iran-linked hackers expand infrastructure across Europe and Middle East, report says Iranian-linked hackers, known as Tortoiseshell, are expanding their operations across Europe and the Middle East, including establishing infrastructure in Britain. The group, associated with Iran's Islamic Revolutionary Guard Corps, utilizes tools like a TwoStroke backdoor and reverse SSH tunnels to conduct espionage o… The Record · 4d ago High UKBESAiranaptssh tunnel
threat-intel Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler Iranian state-sponsored hacking group Nimbus Manticore (linked to Charming Kitten) has expanded its toolset with a TWOSTROKE-like backdoor and SSH tunneling utility, furthering its espionage activities targeting defense,… The Hacker News · 4d ago High IRMIEUsshbackdoorc2
threat-intel Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind Two recent surveys reveal a significant disconnect between contractors’ confidence in their CMMC compliance and their ability to actually prove it. Despite high levels of self-reported confidence, a substantial portion s… SecurityWeek · Aug 21, 2026 High cmmcdfarscybersecurity
vulnerability NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands A security vulnerability in NASA/JPL's AMMOS Instrument Toolkit's AIT-GUI browser-based operator console allows unauthenticated attackers to issue arbitrary commands to spacecraft and instruments. Researchers at Cycode d… The Hacker News · Aug 20, 2026 High CVE-2026-60112CVE-2026-47731CVE-2026-71214browserauthenticationcommand-injection
threat-intel ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More This week saw a surge in exploitation activity and new malware discoveries. A China-nexus APT is leveraging a newly patched VMware vulnerability to deploy a backdoor and ransomware (Babuk-derived). Simultaneously, a zero… The Hacker News · Aug 17, 2026 High CVE-2026-59310CVE-2026-65400CVE-2026-68820CHNOFRexploitvulnerabilityransomware
threat-intel 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft The ‘Jewelbug’ APT group, operating out of China, balances state-sponsored espionage and cryptocurrency theft, targeting governments, military organizations, and corporations globally. They utilize a custom command-and-c… Dark Reading · Aug 13, 2026 High CHMISOcyber espionagecryptocurrency theftnation-state
threat-intel Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor The Lazarus Group, a North Korean threat actor, is exploiting a newly patched zero-day vulnerability in Microsoft Windows' AFD.sys driver to gain SYSTEM access and deploy a backdoor called Troy. They are leveraging a sop… The Hacker News · Aug 12, 2026 High CVE-2026-68820CVE-2025-49113FRGEBRzero-daysocial engineeringphishing
vulnerability Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery Microsoft released a massive update with 62 critical and 357 important security vulnerabilities, marking a significant increase in the number of flaws discovered and highlighting the growing role of AI in vulnerability d… The Record · Aug 12, 2026 High CVE-2026-68820CVE-2026-62832vulnerabilitypatch tuesdayai
threat-intel CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign The CISA has ordered federal agencies to patch a critical Windows vulnerability being actively exploited by North Korean hackers as part of Operation ‘Dream Job’. This campaign, led by the Lazarus Group, impersonates rec… The Record · Aug 12, 2026 Critical CVE-2026-68820FRGEBRzero-daynorth koreaoperation dream job
threat-intel Fresh Windows Zero-Day Exploited in North Korean Cyberattacks North Korean hackers, operating under the Lazarus Group, are exploiting a recently patched Windows zero-day vulnerability (CVE-2026-68820) to conduct targeted attacks against defense, aerospace, and aviation organization… SecurityWeek · Aug 12, 2026 High CVE-2026-68820CVE-2025-49113FRGEBRzero-daylazarus groupcyber espionage
threat-intel Military device manufacturer discloses cyber incident to SEC IEH Corporation, a military device manufacturer, suffered a cyberattack after an employee fell victim to a phishing scheme, gaining unauthorized access to their email account. The attackers accessed sensitive data includ… The Record · Aug 7, 2026 Medium INUSphishingcyberattackdata-breach
threat-intel In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street Several significant cybersecurity events are unfolding this week, including a coordinated AI-powered scam network originating in Cambodia, a data breach at Amgen, a supply chain attack targeting QuickFox VPN, and a serie… SecurityWeek · Aug 7, 2026 High CHCAUSsupply-chainphishingransomware
threat-intel ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks This week’s cybersecurity recap highlighted a concerning trend of AI-powered exploit generation, alongside a series of high-impact security incidents. A vulnerability in Coldcard hardware wallets led to an $88.6 million… The Hacker News · Aug 3, 2026 High CVE-2026-42897CVE-2026-66066CVE-2026-48449USIRaiexploithardware wallet
threat-intel Laundry Bear’s webmail hackers had more in store after February, report says Laundry Bear, a Russian state-linked APT group, has been aggressively exploiting vulnerabilities in both Zimbra Collaboration Suite’s webmail platform and Microsoft Outlook Web Access (OWA) to steal emails and credential… The Record · Jul 29, 2026 High CVE-2026-42897NLUSRUaptvulnerabilityzero-day
threat-intel Mirage Kitten targets Middle East and Africa region with new malware The advanced persistent threat (APT) group Mirage Kitten, also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore, is aggressively targeting sectors in the Middle East and Africa, including aerospace, aviation, tele… Securelist · Jul 28, 2026 High EGJOTAaptmalwarethreat-intel
vulnerability PTC Windchill Vulnerability Exploited in Ransomware Campaign A critical remote code execution vulnerability in PTC's Windchill and FlexPLM PLM platforms has been exploited by a Cl0p ransomware affiliate in a targeted campaign. The attackers are leveraging a chain of vulnerabilitie… SecurityWeek · Jul 27, 2026 Critical CVE-2026-12569rcevulnerabilityransomware
threat-intel Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE Threat actors linked to the Cl0p ransomware group are exploiting internet-exposed PTC Windchill and FlexPLM deployments to gain unauthenticated remote code execution and steal sensitive data for extortion. The campaign l… The Hacker News · Jul 25, 2026 Critical CVE-2026-12569vulnerabilityransomwaredata-breach
threat-intel Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday The Department of War has temporarily paused the mandatory third-party assessment requirement for CMMC Phase 2, citing concerns about the capacity of the assessor ecosystem and the potential for CMMC to price small and m… SecurityWeek · Jul 17, 2026 High cmmccybersecuritycompliance
vulnerability Gitea Vulnerability Exposes Private Container Images without Authentication A significant vulnerability (CVE-2026-27771) has been identified in Gitea, a popular open-source Git repository hosting platform. The flaw allows unauthorized access to private container images, exposing sensitive data w… The Hacker News · May 27, 2026 High CVE-2026-27771CNUSDEcontainergitvulnerability
threat-intel Iranian APT Targets Aviation, Software Companies With Updated Tools The Iranian APT group, known as Nimbus Manticore, has been aggressively updating its tactics and tools to target aviation and software companies globally. The group, linked to Charming Kitten and the IRGC, is employing… SecurityWeek · May 26, 2026 High AEIRSAaptphishingappdomain